Back to Practice
Challenge

Lock It Down

An exam-pace security drill: enforce the restricted Pod Security Standard and a token-hardened ServiceAccount, deploy a workload hardened enough to be admitted under it, then isolate it with a NetworkPolicy and scope its RBAC. Every field is graded.

Your mission

A drill, not a tutorial: paced and scored like the exam, each task fuses several CKS techniques, the specs are exact, and hints cost real points. Work in the secure namespace (already created). The bar is to finish without opening a hint.

You're hardening api end to end — the namespace policy, the workload's identity and security context, its network exposure, and its RBAC. A single missed field (readOnlyRootFilesystem, an auto-mounted token, the wrong policy peer) is a missed mark, exactly as on exam day.

Save typing

kubectl config set-context --current --namespace=secure

Skills you'll put into practice

cksexam-drillsecurityhardening

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation